CVE-2012-2269 – ownCloud 3.0.0 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2012-2269
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary field to apps/contacts/ajax/addcard.php, (2) the parameter parameter to apps/contacts/ajax/addproperty.php, (3) the name parameter to apps/contacts/ajax/createaddressbook, (4) the file parameter to files/download.php, or the (5) name, (6) user, or (7) redirect_url parameter to files/index.php. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en ownCloud v3.0.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) un campo arbitrario a apps/contacts/AJAX/addcard.php, (2) el parámetro 'parameter' a apps/contacts/AJAX/addproperty.php, (3) el parámetro 'name a apps/contacts/AJAX/createaddressbook, (4) el parámetro 'file' a files/download.php, o los parámetros (5) 'name', (6) 'user', o (7) 'redirect_url' a files/index.php. ownCloud version 3.0.0 suffers from cross site scripting and open redirection vulnerabilities. • http://archives.neohapsis.com/archives/bugtraq/2012-04/0127.html http://osvdb.org/81206 http://osvdb.org/81207 http://osvdb.org/81208 http://osvdb.org/81209 http://osvdb.org/81210 http://owncloud.org/security/advisories/CVE-2012-2269 http://secunia.com/advisories/48850 http://www.openwall.com/lists/oss-security/2012/08/11/1 http://www.openwall.com/lists/oss-security/2012/09/02/2 http://www.securityfocus.com/bid/53145 http://www.tele-consulting.com& • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •